From Vietnam to Afghanistan: 30 Years of Service – We Are The Mighty
Six years ago, Dutch intelligence agents reportedly infiltrated a malicious group of hackers working out an office building not far from the Kremlin. Dutch agents hacked into a security camera that monitored people entering the Moscow building, according to the Dutch newspaper de Volkskrant; they also reportedly monitored in 2016 as the hackers broke into the servers of the U.S. Democratic Party.
The hackers came to be known as APT-29 or The Dukes, or more commonly, Cozy Bear, and have been linked to Russias security agencies. According to the report, the Dutch findings were passed onto U.S. officials, and may have been a key piece of evidence that led U.S. authorities to conclude the Kremlin was conducting offensive cyberoperations to hack U.S. political parties during the 2016 presidential campaign.
Fast forward to 2020: the Cozy Bear hackers are back though for those watching closely, they never really went anywhere.
British, American, and Canadian intelligence agencies on July 16 accused Cozy Bear hackers of using malware and so-called spear-phishing emails to deceive researchers at universities, private companies, and elsewhere.
The goal, the agencies said, was to steal research on the effort to create a vaccine for the disease caused by the new coronavirus, COVID-19.
APT-29 is likely to continue to target organizations involved in COVID-19 vaccine research and development, as they seek to answer additional intelligence questions relating to the pandemic, the British National Cyber Security Center said in a statement, released jointly with the Canadian and U.S. agencies.
Its totally unacceptable for Russian intelligence services to attack those who are fighting the coronavirus pandemic, British Foreign Secretary Dominic Raab said.
Kremlin spokesman Dmitry Peskov called the accusations unacceptable.
We can say only one thing: that Russia has nothing to do with these attempts, he told reporters.
The advisory did not name which companies or organizations had been targeted, nor did it say whether any specific data was actually stolen. The head of the British National Cyber Center said the penetrations were detected in February and that there was no sign any data had actually been stolen.
The advisory did say the hackers exploited a vulnerability within computer servers to gain initial footholds and that they had used custom malware not publicly associated with any campaigns previously attributed to the group.
Russias main intelligence agencies are believed to all have offensive cybercapabilities of one sort or another.
Cyber-researchers say Cozy Bear most likely is affiliated with Russias Foreign Intelligence Service, known as the SVR, possibly in coordination with the countrys main security agency, the Federal Security Service (FSB).
According to researchers, the groups origins date back to at least 2008 and it has targeted companies, universities, research institutes, and governments around the world.
The group is known for using sophisticated techniques of penetrating computer networks to gather intelligence to help guide Kremlin policymakers.
It is not, however, known for publicizing or leaking stolen information, something that sets it apart from a rival intelligence agency whose hacking and cyberoperations have been much more publicized in recent years the military intelligence agency known widely as the GRU.
GRU hackers, known as Fancy Bear, or APT-28, have been accused of not only hacking computer systems, but also stealing and publicizing information, with an eye toward discrediting a target. U.S. intelligence agencies have accused GRU hackers of stealing documents from U.S. Democratic Party officials in 2016, and also of leaking them to the public in the run-up to the November presidential election.
The GRU had multiple units, including Units 26165 and 74455, engaged in cyber operations that involved the staged releases of documents stolen through computer intrusions, Special Counsel Robert Mueller wrote in a July 2018 indictment that charged 12 GRU officers. These units conducted large-scale cyber operations to interfere with the 2016 U.S. presidential election.
Three months later, U.S. prosecutors in Pittsburg, Pennsylvania, issued a related Fancy Bear indictment accusing some of the same officers of conducting a four-year hacking campaign targeting international-sport anti-doping organizations, global soccers governing body, the Organization for the Prohibition of Chemical Weapons, and other groups.
A GRU officer named in the Mueller indictment has also been named by German intelligence as being behind the 2015 hack of the Bundestag.
But unlike the GRU and the Fancy Bear hackers, there has never been any public identification of specific Cozy Bear hackers or criminal indictments targeting them.
The U.S.-based cybersecurity company Crowdstrike, which was the first to publicly document the infiltration of the Democratic National Committee, said in its initial report that both the Cozy Bear and the Fancy Bear hackers had penetrated the committees network, apparently independently of each other.
Its not clear exactly what the motivation of the Cozy Bear hackers might be in targeting research organizations, though like many other nations, Russia is racing to develop a vaccine that would stop COVID-19, and stealing scientific data research might help give Russian researchers a leg up in the race.
Russia has reported more than 765,000 confirmed cases. Its official death toll, however, is unusually low, and a growing number of experts inside and outside the country say authorities are undercounting the fatalities.
In the past, Western intelligence and law enforcement have repeatedly warned of the pernicious capabilities of Russian state-sponsored hackers. In the United States, authorities have sought the arrest and extradition of dozens of Russians on various cybercharges around the world.
As in the Mueller indictments, U.S. authorities have used criminal charges to highlight the nexus between Russian government agencies and regular cybercriminals and also to signal to Russian authorities that U.S. spy agencies are watching.
For example, the Mueller indictment identified specific money transfers that the GRU allegedly made using the cryptocurrency bitcoin to buy server capacity and other tools as part of its hacking campaigns.
As of last year, those efforts had not had much effect in slowing down state-sponsored hacking, not just by Russia, but also by North Korea, Iran, China, and others.
[I]n spite of some impressive indictments against several named nation-state actors their activities show no signs of diminishing, Crowdstrike said in a 2019 threat report.
Gleb Pavlovsky, a Russian political consultant and former top Kremlin adviser, downplayed the Western allegations.
We are talking about the daily activities of all secret services, especially regarding hot topics like vaccine secrets, he told Current Time. Of course, they are all being stolen. Of course, stealing is not good, but secret services exist in order to steal.
In the U.S. Congress, some lawmakers signaled that the findings would add further momentum to new sanctions targeting Russia.
It should be clear by now that Russias hacking efforts didnt stop after the 2016 election, Mark Warner, the top Democrat on the U.S. Senate Intelligence Committee, said in a statement.
This article originally appeared on Radio Free Europe/Radio Liberty. Follow @RFERL on Twitter.
Read more:
From Vietnam to Afghanistan: 30 Years of Service - We Are The Mighty
- "Just bread and tea": WFP says aid cuts to Afghanistan leave millions hungry this winter - Reuters - January 27th, 2025 [January 27th, 2025]
- Cricket Australia boss backs players to express own views on facing Afghanistan - The Guardian - January 27th, 2025 [January 27th, 2025]
- Afghanistan: Filmmaker tortured and denied care in Taliban prison - Amnesty International - January 27th, 2025 [January 27th, 2025]
- Ex-police chief condemns investigation into alleged Afghanistan war crimes by UK Special Forces - Sky News - January 27th, 2025 [January 27th, 2025]
- UN report: Armed attacks, explosions kill 18 in Afghanistan over three months - Amu TV - January 27th, 2025 [January 27th, 2025]
- Afghanistan: Mapping of Humanitarian Health Facilities Supported by Health Cluster Partners (December 2024) - ReliefWeb - January 27th, 2025 [January 27th, 2025]
- Uzbekistan Extends Agreement on Hairaton-Mazar-e-Sharif Railway with Afghanistan - Times of Central Asia - January 27th, 2025 [January 27th, 2025]
- Afghanistan: ES-NFI Cluster Winterization Capacity (as of 15 January 2025) - ReliefWeb - January 27th, 2025 [January 27th, 2025]
- "Just bread and tea": WFP says aid cuts to Afghanistan leave millions hungry this winter - MSN - January 27th, 2025 [January 27th, 2025]
- First Iran FM visit to Afghanistan since Taliban takeover focuses on water, migration, security - Middle East Monitor - January 27th, 2025 [January 27th, 2025]
- Afghanistan womens team set to take the field after 2021 - The Times of India - January 27th, 2025 [January 27th, 2025]
- Statement of ICC Prosecutor Karim A.A. Khan KC: Applications for arrest warrants in the situation in Afghanistan - the International Criminal Court - January 24th, 2025 [January 24th, 2025]
- Exiled Afghanistan women players to men's team: 'Please be the voice of the girls' - ESPNcricinfo - January 24th, 2025 [January 24th, 2025]
- Taliban announce release of two Americans held in Afghanistan in a prisoner exchange - NPR - January 24th, 2025 [January 24th, 2025]
- Afghanistan: The price of peace - Al Jazeera English - January 24th, 2025 [January 24th, 2025]
- 2 Americans freed from Afghanistan in prisoner swap, family and Taliban say - ABC News - January 24th, 2025 [January 24th, 2025]
- How the Taliban restrict women's lives in Afghanistan - The Times of India - January 24th, 2025 [January 24th, 2025]
- International Criminal Court seeking arrests over LGBTQ+ and gender persecution in Afghanistan - PinkNews - January 24th, 2025 [January 24th, 2025]
- Funding cuts to Afghanistan are the biggest threat to helping women, aid agency chief warns - ABC News - January 24th, 2025 [January 24th, 2025]
- Afghanistan refugees plead with Trump to be exempt from relocation: 'Many of us risked our lives to support the U.S. mission' - Fortune - January 24th, 2025 [January 24th, 2025]
- U.S. and Afghanistan carry out prisoner swap, confirm Taliban and family - UPI News - January 24th, 2025 [January 24th, 2025]
- AFGHANISTAN ICC to consider arrest warrant for Taliban leaders, increasingly divided among themselves - AsiaNews - January 24th, 2025 [January 24th, 2025]
- For Trumps national security adviser, Afghanistan still looms large - The Washington Post - January 24th, 2025 [January 24th, 2025]
- How the Taliban restrict women's lives in Afghanistan - Wyoming Tribune - January 24th, 2025 [January 24th, 2025]
- Austin, the first Black defense secretary, ends his term marred by Afghanistan but buoyed by Ukraine - The Associated Press - January 24th, 2025 [January 24th, 2025]
- ISIS claims killing of Chinese national in Afghanistan - ShiaWaves | Shia World News - January 24th, 2025 [January 24th, 2025]
- Taliban announce the release of two Americans held in Afghanistan in a prisoner exchange - The Hindu - January 24th, 2025 [January 24th, 2025]
- US offered to swap Guantanamo prisoner to free detained Americans in Afghanistan - CNN - January 7th, 2025 [January 7th, 2025]
- England-Afghanistan boycott calls: MP says players have 'power' to refuse to play Champions Trophy match - BBC.com - January 7th, 2025 [January 7th, 2025]
- Opinion | A long time under the snow for the women of Afghanistan - The Washington Post - January 7th, 2025 [January 7th, 2025]
- Special forces Afghanistan murders whistleblower fears being branded traitor - The Independent - January 7th, 2025 [January 7th, 2025]
- Afghanistan and Pakistan on the brink of war - Israel Hayom - January 7th, 2025 [January 7th, 2025]
- From Afghanistan to Virginia the Muslims who fought in the American Civil War - Aeon - January 7th, 2025 [January 7th, 2025]
- Opinion | America, Afghanistan and the Price of Self-Delusion - The New York Times - January 7th, 2025 [January 7th, 2025]
- Deadly cross-border attacks taking toll on Pakistan, Afghanistan - Al Jazeera English - January 7th, 2025 [January 7th, 2025]
- Soldier who died by suicide in Las Vegas told ex-girlfriend of pain and exhaustion after Afghanistan - The Associated Press - January 7th, 2025 [January 7th, 2025]
- British Afghanistan whistleblower feared for personal safety, inquiry hears - The National - January 7th, 2025 [January 7th, 2025]
- With Islamist Terrorism on the Rise in Afghanistan and Foes Such as Communist China Gaining Power There, America May Need To Pivot - The New York Sun - January 7th, 2025 [January 7th, 2025]
- SAS accused of war crimes in Afghanistan by rival unit chief - The Telegraph - January 7th, 2025 [January 7th, 2025]
- Keir Starmer calls on ICC to 'deliver own rules' amid Afghanistan boycott row - ESPNcricinfo - January 7th, 2025 [January 7th, 2025]
- Sports activist says governing bodies have failed the women of Afghanistan - Sky News - January 7th, 2025 [January 7th, 2025]
- Russia invaded Ukraine after witnessing US troop withdrawal from Afghanistan - Trump - RBC-Ukraine - January 7th, 2025 [January 7th, 2025]
- ECB Rejects Call For Boycott Of Afghanistan Champions Trophy Game: Report - NDTV Sports - January 7th, 2025 [January 7th, 2025]
- Seven-wicket Rashid leads Afghanistan to Test series win over Zimbabwe - Al Jazeera English - January 7th, 2025 [January 7th, 2025]
- UK government urges cricket chiefs to 'deliver on own rules' after Afghanistan boycott calls - Hindustan Times - January 7th, 2025 [January 7th, 2025]
- Army says New Years bombers overlapped at Fort Liberty and were both in Afghanistan 'surge' - Task & Purpose - January 7th, 2025 [January 7th, 2025]
- Champions Trophy 2025: England team urged to boycott game against Afghanistan over Taliban suppression of womens rights - The Hindu - January 7th, 2025 [January 7th, 2025]
- ECB rejects calls for England to boycott Afghanistan match in 2025 Champions Trophy - Hindustan Times - January 7th, 2025 [January 7th, 2025]
- Champions Trophy: ECB rejects call for boycott of Afghanistan game, says report - The Times of India - January 7th, 2025 [January 7th, 2025]
- England reject calls to boycott Afghanistan match, saying cricket is source of hope - The Independent - January 7th, 2025 [January 7th, 2025]
- Champions Trophy: England Urged To Boycott Afghanistan Match By British Politicians. Here's Why - NDTV Sports - January 7th, 2025 [January 7th, 2025]
- ECB Chief Richard Gould rejects calls for England to boycott Champions Trophy match against Afghanistan - TheNewsMill - January 7th, 2025 [January 7th, 2025]
- Why are relations between Pakistan and Afghanistan so tense? - Al Jazeera English - December 30th, 2024 [December 30th, 2024]
- Ignoring Warnings, a Growing Band of Tourists Venture to Afghanistan - The New York Times - December 30th, 2024 [December 30th, 2024]
- In Syria, U.S. Hopes to Avoid Replay of Afghanistan - The New York Times - December 30th, 2024 [December 30th, 2024]
- Afghanistan play out first wicketless day in Tests in five years | Tap to know more | Inshorts - Inshorts - December 30th, 2024 [December 30th, 2024]
- The Taliban order all NGOs in Afghanistan to stop employing women or face closure - The Associated Press - December 30th, 2024 [December 30th, 2024]
- Is it time to recognise the Taliban government in Afghanistan? - The Conversation France - December 30th, 2024 [December 30th, 2024]
- Airstrikes target suspected Pakistani Taliban hideouts in Afghanistan - The Associated Press - December 30th, 2024 [December 30th, 2024]
- Taliban say Pakistani airstrikes killed 46 people in eastern Afghanistan, mostly women and children - The Associated Press - December 30th, 2024 [December 30th, 2024]
- In Afghanistan, Trump will have to play a balancing game - Al Jazeera English - December 30th, 2024 [December 30th, 2024]
- The Taliban order all NGOs in Afghanistan to stop employing women or face closure - The Caledonian-Record - December 30th, 2024 [December 30th, 2024]
- Afghanistan: A Friendly Brother Country And The Target Of Airstrikes Was TTP Khawarjis OpEd - Eurasia Review - December 30th, 2024 [December 30th, 2024]
- Taliban say Pakistani airstrikes killed 46 people in eastern Afghanistan, mostly women and children - ABC News - December 30th, 2024 [December 30th, 2024]
- What happened to the iconic Humvees US forces left behind in Afghanistan? - The Independent - December 30th, 2024 [December 30th, 2024]
- Afghanistan: Mapping of Humanitarian Health Facilities Supported by Health Cluster Partners (November 2024) - ReliefWeb - December 30th, 2024 [December 30th, 2024]
- Afghanistan: Now It Can Be Told, After All The Harm Has Been Done OpEd - Eurasia Review - December 30th, 2024 [December 30th, 2024]
- Taliban say Pakistani airstrikes killed 46 people in eastern Afghanistan, mostly women and children - The Indian Express - December 30th, 2024 [December 30th, 2024]
- Pakistan, Afghanistan Agree On Truce After Pak Claims Taliban Forces Targeted Its Outposts - WION - December 30th, 2024 [December 30th, 2024]
- Greek authorities say boat capsizing victims and survivors were from Afghanistan. 2 Turks arrested - The Associated Press - December 22nd, 2024 [December 22nd, 2024]
- Withdrawal of United States troops from Afghanistan | Explanation & Impact - Britannica - December 22nd, 2024 [December 22nd, 2024]
- Julani tells BBC: This is not Afghanistan, we will educate women - The Jerusalem Post - December 22nd, 2024 [December 22nd, 2024]
- Pakistan Soldiers Killed in Border Area with Afghanistan - Modern Tokyo Times - December 22nd, 2024 [December 22nd, 2024]
- Rising Traffic Incidents in Afghanistan: 190 Lives Lost and 400 Injured in the Past Three Months - Hasht-e Subh Daily - December 22nd, 2024 [December 22nd, 2024]
- Ghazanfar five-for leads Afghanistan to ODI series win over below-par Zimbabwe - ESPNcricinfo - December 22nd, 2024 [December 22nd, 2024]
- After emigrating from Afghanistan, a young wrestler feels at home on the mat - The Washington Post - December 22nd, 2024 [December 22nd, 2024]
- Following Afghanistan, Syria cements the end of Americas War on Terror era - Observer Research Foundation - December 22nd, 2024 [December 22nd, 2024]
- Blinken defends Afghanistan withdrawal at contentious House hearing - CBS News - December 12th, 2024 [December 12th, 2024]
- U.S. condemn move to suspend medical education for women in Afghanistan - NBC News - December 12th, 2024 [December 12th, 2024]
- Netanyahu regales court with story of John Kerrys invitation to visit Afghanistan - The Times of Israel - December 12th, 2024 [December 12th, 2024]